Going live
Everything to check before you take real payments, and after.
During the beta, test and live keys act on the same business: what you create with a test key shows up in your dashboard and in every list, like anything else, and every event's
mode is live. On a live business a test key can read everything, but creating a payment, a checkout or a remainder, or changing what customers see or pay, answers 403 test_mode_unavailable, so a test key never moves real money or changes a live checkout. See test and live keys. Everything you tried while building is already in your live data, so review it before launch.Before you launch
0 of 6 done
- Swap your
402s_test_key for a402s_live_one in your production environment, and restrict it to the resources your server uses. simulateandPOST /checkouts/{id}/mark-sentexist for testing. Make sure production code never sends either.- Subscribe to
payment.succeeded, pluspayment.underpaidandpayment.needs_reviewif you handle them, verify every signature, and skip deliveries whosewebhook-idyou've already handled. - Point
success_urlandcancel_urlat your production pages, on each payment or link. They must usehttps://;http://works only forlocalhostand127.0.0.1. - Pick your coins and networks, and turn cards on or off, in Settings, under Payments.
- Run each simulated outcome through your integration, including underpaid and late transfers and declined cards.
Secure your account
0 of 5 done
- Settings, under General. It signs in without a password or two-step code, and works only on 402pay's own site, so it can't be phished.
- A password manager can make one for you. Change it in Settings if someone may have seen it; that signs out your other devices.
- Settings, under General. Store the recovery codes somewhere other than your authenticator.
- Password resets and security emails go to the address you sign in with, so protect that mailbox with two-step verification too.
- Keep your recovery phrase and encryption password somewhere safe and offline. 402pay can't recover either one.
After launch
- Watch webhook deliveries in the dashboard, and resend any that failed.
- Handle underpaid and late payments as they come in, so no customer is left waiting.
- Rotate a webhook secret or API key whenever someone with access leaves your team.